PortSwigger Web Security Academy: basic server-side template injection in an ERB message parameter, escalated to command execution.
Basic Server-Side Template Injection

ls -la posts/
Writeups, tooling notes, and certification experiences, spanning general techniques and tool guides. Jump to the labs section , or the machines section for box walkthroughs.
ls tags/ # browse by topic

PortSwigger Web Security Academy: basic server-side template injection in an ERB message parameter, escalated to command execution.

PortSwigger Web Security Academy: blind OS command injection where the output is redirected to a file in the web root and retrieved through the image endpoint.

PortSwigger Web Security Academy: blind OS command injection detected with a time delay, injecting ping into the feedback email parameter.

PortSwigger Web Security Academy: OS command injection (simple case). Injecting whoami into an unsanitized stock-checker storeID parameter with Burp.

An easy OffSec Proving Grounds Linux box chaining an exposed source backup, a PHP type-juggling auth bypass, LFI in the admin panel, hash cracking, and a sudo wildcard to root.